Loading HuntDB...

GHSA-x733-8f5f-m9rp

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

In Splunk Enterprise versions below 8.2.9 and 8.1.12, the way that the rex search command handles field names lets an attacker bypass SPL safeguards for risky commands https://docs.splunk.com/Documentation/SplunkCloud/latest/Security/SPLsafeguards . The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The attacker cannot exploit the vulnerability at will.

Related CVEs

Key Information

GHSA ID
GHSA-x733-8f5f-m9rp
Published
November 5, 2022 12:00 PM
Last Modified
November 8, 2022 7:00 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.